Skip to main content

Users & Roles

The Users module manages team members within your organization. Administrators can invite new users, assign roles, manage module-level access, and enable or disable accounts. All role and status changes sync with AWS Cognito immediately.

Overview

Access from Administration → Users in the sidebar. The page has two tabs:

Users page showing Members tab active with Invite User button, four stat cards (Total Users 6, Active 6, Pending 0, Disabled 0), search bar with All Statuses filter, and user table with columns for Name, Email, Role, Status, Job Title, Department, and Last Login showing 6 users including Admin, User, and Viewer roles all with active status
  • Members — User list with status cards, search, and detail sidecar
  • Module Access Roles — Granular module-level permission roles

Stat Cards

CardDescription
Total UsersAll users in the organization
ActiveUsers who can log in
PendingInvited but haven't accepted yet
DisabledDeactivated accounts

User Table

ColumnDescription
NameUser's full name (click to open detail sidecar)
EmailLogin email address
RoleColor-coded role badge
StatusActive (green), Pending (amber), or Disabled (red)
Job TitleUser's job title
DepartmentAssigned department
Last LoginMost recent login date, or "Never"

Use the search bar to find users by name, email, job title, or department. Filter by status using the dropdown.

Inviting Users

Click + Invite User to open the invitation dialog.

  1. Enter email — The system checks if the email belongs to an existing platform user
  2. Select role — Choose a tenant role (Admin, User, Auditor, or Executive)
  3. Set module access — Optionally assign a Module Access Role for granular permissions
  4. Add profile details — Job title, department, and phone (for new users)
  5. Send invitation — The user receives an email to set up their account

If the email belongs to an existing platform user, they're added to your tenant without creating a new account.

User Detail

User detail sidecar showing Michael Scott with Active status badge and Admin role badge, Profile section with email, Full Name, Job Title (CISO), Department dropdown, Manager dropdown, and Phone fields, Role section with Admin dropdown, and metadata showing Invited by System, Last login 5/4/2026, Created 3/3/2026

Click any user row to open the detail sidecar. All profile fields autosave on change.

Profile

FieldDescription
EmailLogin email (display only)
Full NameUser's display name
Job TitlePosition title
DepartmentDropdown from organization's departments
ManagerDropdown from organization's users
PhoneContact phone number

Role

Change the user's role using the dropdown. The change takes effect immediately on their next page load. Administrators cannot modify their own role.

Module Access

For non-admin users, you can assign a Module Access Role or customize per-module access:

  • Module Access Role — Select a predefined role that grants access to specific modules
  • Custom Override — Toggle individual module access with per-module checkboxes

Actions

The overflow menu (three dots) provides additional actions:

ActionDescription
Resend InviteResend the invitation email (for pending users)
Reset PasswordTrigger a password reset via email
Disable AccountPrevent the user from logging in (preserves data attribution)
Enable AccountRe-enable a disabled account
Remove from OrgRemove the user from your organization (destructive, with confirmation)

Metadata

The bottom of the sidecar shows:

  • Invited by — Who invited this user
  • Last login — Most recent login date
  • Created — Account creation date

Roles

Tenant Roles

RoleColorAccess Level
AdminIndigoFull access — manage settings, users, data, integrations
UserSkyRead/write data — cannot manage users or settings
AuditorAmberRead-only — can view and export, cannot edit
ExecutiveEmeraldDashboard-only — high-level visibility

Role Permissions

Permission AreaAdminUserAuditorExecutive
View dashboardsYesYesYesYes
Read dataYesYesYesLimited
Create/edit dataYesYesNoNo
Delete dataYesNoNoNo
Manage usersYesNoNoNo
Manage settingsYesNoNoNo
Manage integrationsYesNoNoNo
View reportsYesYesYesYes
Generate reportsYesNoNoNo
Export dataYesYesYesNo

See Roles & Permissions for detailed permission breakdowns.

Module Access Roles

The Module Access Roles tab lets you create reusable permission profiles that control which platform modules a user can access.

Each role defines:

  • Name — Role name (e.g., "Compliance Team", "Security Analyst")
  • Description — What this role is for
  • Module Keys — Which modules are accessible
  • Full Access — Toggle to grant access to all modules

Assign Module Access Roles to users during invitation or from the user detail panel. All members with a given role inherit changes immediately when the role is updated.

User Statuses

StatusColorDescription
ActiveGreenUser can log in and use the platform
PendingAmberInvitation sent, user hasn't completed account setup
DisabledRedAccount deactivated, user cannot log in

Deactivated users retain their data attribution (created by, assigned to) across all records.

Key Contacts

Access from Administration → Key Contacts.

Key Contacts are designated individuals for specific compliance roles (e.g., CISO, DPO, Privacy Officer). These contacts appear in assessment reports and are used for automated notifications. Unlike regular users, key contacts don't need a platform login — they can be external individuals.

Support Access

Tenants can grant temporary access to the Concerto support team for troubleshooting:

DurationDescription
24 hoursShort-term support session
7 daysExtended troubleshooting
30 daysLonger engagement
IndefiniteUntil manually revoked

All support access grants are logged in an audit trail. Access can be revoked at any time from Administration → Settings.